Progression of GoCaracal delivery via phishing | Image: Arctic Wolf Labs
At a Glance
| Category | Details |
|---|---|
| Threat Actor | Dark Caracal (suspected connection to Lebanese GDGS) |
| Activity Type | Cyberespionage, credential harvesting, and malware delivery |
| Targets | Communications firm in Venezuela; broader Latin American entities |
| Scale | Targeted corporate intrusion; 249 related malware samples identified |
| Law Enforcement Status | Unindicted; monitored by commercial cybersecurity intelligence teams |
| Primary Sources | Arctic Wolf Labs and Kaspersky |
TL;DR
In June 2026, security researchers investigated a targeted cyber intrusion against a telecommunications organization in Venezuela. The attackers deployed the newly discovered GoCaracal malware framework alongside an updated Bandook trojan variant. This campaign demonstrates that the group is modernizing its tooling while maintaining historic regional targets.
What Happened in the Venezuela Intrusion
Attackers initiated the intrusion using phishing emails containing weaponized SVG attachments. When victims opened these vector files, embedded scripts redirected browsers through intermediate URL shorteners. Ultimately, the multi-stage delivery chain downloaded a password-protected archive from an attacker-controlled staging site.
Inside the archive, an executable established the initial foothold on the victim machine. The operators then utilized this bridge to deploy additional payloads, including Bandook and an extended implant. According to the advisory, “These findings show that Dark Caracal is modernizing the malware and infrastructure behind its established operations and tradecraft.”
The newly identified GoCaracal malware operates across two distinct build profiles. First, the lightweight profile focuses on system profiling, remote shell control, and payload delivery. It communicates through an AES-GCM encrypted protocol using numeric packet identifiers. Second, the extended profile provides an intelligence collection framework with 34 command handlers. This larger implant harvests browser credentials from Chrome, Brave, and Firefox. Additionally, it enables WebRTC remote desktop streams and in-band SOCKS5 proxy routing.
Furthermore, the extended build introduces blockchain-based command-and-control fallback mechanisms. If primary communication channels fail, the implant queries an Ethereum smart contract. Specifically, the malware calls the eth_getStorageAt function via public JSON-RPC nodes to read fallback IP addresses. As the report explains, “This mechanism does not place the malware’s full command-and-control channel on Ethereum.” Instead, the smart contract functions as a resilient dead-drop resolver.
Attribution and Threat Actor Profile
Arctic Wolf Labs attributes this activity to Dark Caracal with medium confidence. Security analysts historically link this cyberespionage group to Lebanon’s General Directorate of General Security (GDGS). The team stated, “We assess with medium confidence that this activity is linked to Dark Caracal, a cyberespionage group associated with Lebanon’s General Directorate of General Security (GDGS) that has historically targeted governments, businesses, journalists, and activists.”
The attribution rests upon overlapping delivery infrastructure, Spanish-language financial lures, and recurring Delphi loader code. Earlier in 2026, Kaspersky documented a related Dark Caracal campaign deploying the C++ backdoor AsioGate. While GoCaracal does not share direct source code with AsioGate, both implants serve similar operational roles. Furthermore, Dark Caracal deployed GoCaracal alongside Bandook, a tool long associated with Lebanese state-aligned cyber campaigns.
Impact and Regional Scale
The investigated intrusion compromised an enterprise communications firm in Venezuela. However, forensic evidence suggests the campaign targeted multiple organizations across Latin America. Researchers identified 249 related framework samples compiled between January and July 2026.
Telemetry uncovered associated artifacts and delivery infrastructure linked to Brazil, Chile, Colombia, Ecuador, El Salvador, and Uruguay. Moreover, the attackers isolate their operational components by separating delivery infrastructure from backend servers. For instance, the group hosted 23 out of 24 GoCaracal control servers on AEZA Group networks. In contrast, they hosted Bandook infrastructure on AlexHost systems. This operational separation prevents the takedown of one hosting provider from neutralizing the entire campaign.
How Organizations Can Stay Protected
Organizations must defend against this evolving threat through layered defensive controls. Security teams should implement strict email inspection rules to block untrusted SVG attachments. Additionally, administrators should restrict outbound JSON-RPC connections to public Ethereum nodes from corporate endpoints.
Endpoint detection platforms must monitor unexpected process creation from archive utilities. Security staff should also look for suspicious registry modifications involving hidden user profile directories. Network defenders must inspect internal traffic for unauthorized SOCKS5 proxy connections. Finally, organizations operating in sensitive sectors across Latin America should share telemetry to detect emerging Dark Caracal infrastructure rapidly.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!